Chain Of Custody: A process that tracks the movement and handling of evidence from the moment it is collected until the moment it is presented in court. It includes a written record of all individuals who have had custody of the evidence, documenting each transfer of custody and the reason for the transfer. In digital forensics, maintaining a proper chain of custody is crucial for the integrity of digital evidence. It ensures that digital evidence, such as log files or hard drives, can be verified as being handled and stored in a secure manner, preventing tampering or unauthorized access and making the evidence legally admissible in court.
Categories: CC D5: Security Operations | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D7: Security Operations | Security+ D5: Security Program Management and Oversight | SSCP D4: Incident Response and Recovery
Related Articles: